cbcvebase.

Totolink T8 Firmware vulnerabilities

26 known vulnerabilities affecting totolink/t8_firmware.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH8MEDIUM1

Vulnerabilities

Page 2 of 2
CVE-2024-46419P3CRITICALCVSS 9.8v4.1.5cu.861_b202302202024-09-16
CVE-2024-46419 [CRITICAL] CWE-120 CVE-2024-46419: TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg fu TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.
nvd
CVE-2024-8580P3HIGHCVSS 8.1v4.1.5cu.861_b202302202024-09-08
CVE-2024-8580 [HIGH] CWE-259 CVE-2024-8580: A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This v A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit
nvd
CVE-2024-0569P3CRITICALCVSS 9.1v4.1.5cu.833_202209052024-01-16
CVE-2024-0569 [CRITICAL] CWE-200 CVE-2024-0569: A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This a A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disc
nvd
CVE-2023-24155P3CRITICALCVSS 9.8vv4.1.5cu2023-02-03
CVE-2023-24155 [CRITICAL] CWE-798 CVE-2023-24155: TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.
nvd
CVE-2024-46424P4HIGHCVSS 7.5v4.1.5cu.861_b202302202024-09-16
CVE-2024-46424 [HIGH] CWE-120 CVE-2024-46424: TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomMod TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.
nvd
CVE-2024-0944P4MEDIUMCVSS 5.3v4.1.5cu.833_202209052024-01-26
CVE-2024-0944 [MEDIUM] CWE-613 CVE-2024-0944: A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Aff A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult.
nvd
Totolink T8 Firmware vulnerabilities | cvebase